Short Name |
SMTP:DOS:SENDMAIL-HEADERS-DOS |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
SMTP |
Keywords |
Sendmail Headers Prescan Denial Of Service |
Release Date |
2003/04/25 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against Sendmail versions 8.9.2 and earlier. Attackers can send multiple headers in a maliciously crafted SMTP HELO message to create a denial-of-service attack against the message transfer agent (MTA).
Sendmail has been reported prone to a denial of service vulnerability when handling malicious SMTP mail headers. The vulnerability has been reported to present itself, due to an inefficient implementation of a header prescan algorithm. A remote attacker may reportedly deny service to legitimate users by sending specially crafted emails to the affected service. *** November 20, 2003 - This BID was erroneously updated today regarding the release of IBM AIX APARs released to address the Sendmail vulnerability described in BID 8641. The appropriate updates and changes have been made.